summaryrefslogtreecommitdiff
path: root/debian/local/common-session
diff options
context:
space:
mode:
Diffstat (limited to 'debian/local/common-session')
-rw-r--r--debian/local/common-session5
1 files changed, 3 insertions, 2 deletions
diff --git a/debian/local/common-session b/debian/local/common-session
index 2e94d6c7..1cd4f1ae 100644
--- a/debian/local/common-session
+++ b/debian/local/common-session
@@ -3,8 +3,7 @@
#
# This file is included from other service-specific PAM config files,
# and should contain a list of modules that define tasks to be performed
-# at the start and end of sessions of *any* kind (both interactive and
-# non-interactive).
+# at the start and end of interactive sessions.
#
# As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
# To take advantage of this, it is recommended that you configure any
@@ -20,6 +19,8 @@ session requisite pam_deny.so
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
session required pam_permit.so
+# reset the umask for new sessions
+session optional pam_umask.so
# and here are more per-package modules (the "Additional" block)
$session_additional
# end of pam-auth-update config